Users from an external organization authenticating to a Remote Dekstop App

Hi,
We have set up Remote Desktop Apps using Remote Desktop Services
The apps are permissioned with AD user accounts in our forest
When an external company that has network access (i.e. routable addresses) tries to log in (with credentials in our AD) they sometimes get in and other times do not. They see an error message saying 'The credentials did not work' or 'The Local Security Authority
cannot be contacted'
I think this may be because all the Domain controllers for that domain are not reachable from the external company's PC
i.e. if they get lucky they try and authenticate using a reachable DC but sometimes they pick a DC that is not routable and see this error
Is my thinking correct?
How is a DC chosen by a PC belonging to an external company?
This article leads me to believe it is random:
How Domain Controllers are Located Across Trusts
Thank you for your time

Hope this may help:
"Your credentials did not work" error when connecting to Windows Azure VM's
http://blogs.msdn.com/b/narahari/archive/2011/08/29/getting-quot-your-credentials-did-not-work-quot-when-connecting-to-windows-azure-vm-s.aspx
http://social.technet.microsoft.com/Forums/windows/en-US/5ca3e416-e500-4b7c-a309-f15123914e5b/your-credentials-did-not-work?forum=w7itpronetworking
http://social.technet.microsoft.com/Forums/windowsserver/en-US/aa054168-8811-4329-8eb3-a07be874c71a/your-credentials-did-not-work-the-logon-attempt-failed?forum=winserverDS
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

Similar Messages

  • How do I run users from an external hard drive?

    I used to have a 2 TB hard drive in my iMac. One of the users contains all my music, photos and videos. It's a very large file, of course.
    I have just swapped out the 2 TB drive for a 120 GB SSD and reconnected the 2 TB drive as an external HD. The problem is, I've only got 60 GB of space left on it and that's not enough room for my media user. It's sitting on the external drive but I can't figure out how to access it.
    I would like to be able to (1) run the media user from the external drive or, if that's not possible, (2) move the media user to the SSD but store the music, photos, video etc. on the external HD.
    Any tips? Thanks!

    OK, here's how to do it on Photo Booth. It's a little different for every app, it seems.
    On Photo Booth, you don't use aliases. The app doesn't like them. Instead, start by deleting the Photo Booth Library file in the new user. (You only want to do this if you have no photos in Photo Booth, I assume. Remember I've started with a completely new user.) Then launch Photo Booth. It will tell you there's no library and ask you to either create one or point to one.
    Then point to your Photo Booth Library file on your external drive. (Again, permissions have to be set to allow the SSD drive access.)
    By the way, I am not an expert in any of this. There may be better ways of doing all this, but I couldn't find them on discussions so I'm recording them here in case they help people in future. Feel free to chime in with a more elegant solution, if there is one! But this all does seem to be working so far.

  • Error: System.Management.Automation.RemoteException: Federation information could not be received from the external organization.

    Greetings.
    I'm getting 2 errors and 1 warning in the Hybrid Configuration object:
    INFO : Session=Tenant Cmdlet=Get-FederationInformation -DomainName 'SanJuanCiudadPatria.com' -BypassAdditionalDomainValidation: $true START
    ERROR : System.Management.Automation.RemoteException: Federation information could not be received from the external organization.
    INFO : Session=Tenant Cmdlet=Get-FederationInformation FINISH Time=2620.7003ms
    INFO : Session=Tenant Cmdlet=Get-FederationInformation -DomainName 'SanJuanCiudadPatria.com' -BypassAdditionalDomainValidation: $true START
    ERROR : System.Management.Automation.RemoteException: Federation information could not be received from the external organization.
    INFO : Session=OnPrem Cmdlet=Get-OrganizationConfig START
    INFO : Session=OnPrem Cmdlet=Get-OrganizationConfig FINISH Time=203.229ms
    WARNING : Office 365 was unable to communicate with your on-premises Autodiscover endpoint.  This is typically due to incorrect DNS or firewall configuration.  The Office 365 tenant is currently configured to use the following URL for Autodiscover
    queries from the Office 365 tenant to the on-premises organization - https://autodiscover.SanJuanCiudadPatria.com/autodiscover/autodiscover.svc/WSSecurity. See the following article for further information: http://go.microsoft.com/fwlink/p/?LinkId=275838
    Any help would be greatly appreciated.
    Hello World.

    Hello,
    If the IIS configuration is missing the svc-Integrated handler mapping, the issue may occur. Please try to refer to the following KB to check if the issue can be solved.
    http://support.microsoft.com/kb/2626696
    Please check if there is A record for autodiscover on public DNS server or DNS SRV record.
    Additional blog for your reference.
    http://blogs.technet.com/b/mikehall/archive/2013/08/21/office-365-insight-into-the-hybrid-configuration-wizard-part-2.aspx
    Cara Chen
    TechNet Community Support

  • BPM 11g workspace not show user from OVD - top most authentication provider

    Hi,
    We have added OVD which connected to LDAP as the top-most authentication provider for myrealm. The order of the providers are:
    (1) OVD (control Flag:SUFFICIENT)
    (2) DefaultAuthenticator(control Flag: REQUIRED)
    (3) DefaultIdentityAsserter
    The users and groups from the OVD are displayed in the weblogic console and are searchable in the OEM when I want to add the user/group to the application role but not in the BPM workspace. I find a related thread:
    Weblogic administrator account is inactive after enabling DB Authenticator
    It seems I did the same but I am still able to login bpm workspace with weblogic id. I guess my BPM does not use OVD for the Authenticator at all and it is still using DefaultAuthenticator. Can anyone please help and let me know what I missed for the setting? Should I put DefaultIdentityAsserter to the 2nd in the provider list to solve this?
    Thanks,
    Helen
    Edited by: Helen on Mar 22, 2011 7:31 AM

    Hi Helen
    Make sure that for the second Authenticator (DefaultAuthenticator) the required Flag is SUFFICIENT. From Weblogic point of view, if it is required, this means that user should and must exist in this provider also. Since you configured external LDAP and say you have something like "mytestuser" in LDAP. I guess you already added this user "mytestuser" to the BPMWorflowAdmin role as per the forum you listed below. But this user may not and will not exist in the default authenticator. So try making it sufficient and see if that works.
    As mentioned in my earlier post, I do have LDAP cconfigured to my BPM Domain and this is the first in the order of providers. I added a user from this LDAP into workflow admin role in em. I could login into bpm/workspace and see adminstrator link.
    Thanks
    Ravi Jegga

  • Set User Description by external ldap authenticator

    Hi,
    I used a customized iplanet Authentication Providers to authenticate the user.
    After the system is started and I goes to "Security Realms > myrealm > Users and Groups -> Users", I am able to see a list of user from Ldap server. Name field is username. But description is empty. How could I populate description field by field in External Ldap server?
    Thanks,

    Hi,
    I used a customized iplanet Authentication Providers to authenticate the user.
    After the system is started and I goes to "Security Realms > myrealm > Users and Groups -> Users", I am able to see a list of user from Ldap server. Name field is username. But description is empty. How could I populate description field by field in External Ldap server?
    Thanks,

  • Using users from an external table in the BI Publisher add-in for Word

    After installing the BI Publisher add-in in Word, I find that I can connect to BI Publisher (http://hostname:9704/xmlpserver) only using IDs that are defined within WLS. I'm using an Oracle database table and external authentication to get my users logged in to the Answers environment, and they use the BI Publisher features of Analytics as well. But if I try to connect from the add-in to xmlpserver as one of those externally authenticated users, it fails.
    Do I have to create new users in WebLogic Security for those folks who need to build BIP templates in Word? If not, how can I get the add-in to recognize and use the external table authentication?
    I'm in 11.1.1.6.2 BP1, but I've noticed the problem for a long time, possibly back to 10g.

    As you probably noticed, your formulas won't import into Project Siena - only the data.
    I've created a sample application for you to demonstrate how you create formulas in Project Siena.
    Here's the link to the project:
    https://onedrive.live.com/redir?resid=D64FC13017F614FD!47783&authkey=!AN3UxGDTP1vNbbU&ithint=folder%2cjpg
    In this example, I'm doing the heavy lifting on the Calculate button.
    Here's what I did to create the project.
    I added two input text boxes for height and weight
    I added a calculate button.
    I added a label to display the result.  In the Default Text I added
    BMI which is a context variable.  I could have called it BMIResult - it's up to you.
    Here's the formula for OnSelect of the Calculate button:
    UpdateContext({BMI: Round((Value(txtWeight!Text) / Value(txtHeight!Text * txtHeight!Text)), 2)*703})
    Note: If you haven't done so already, click 'Express View' in the lower right hand corner to see the properties.
    UpdateContext is a formula that is used to change results - in this case the variable, BMI.
    I used the Round function so it displays 2 digits for the decimal.
    I used the Value formula to convert the input boxes to numbers.
    This should get you started in the right direction - let me know if you need further explanation.
    One more thing to add - when creating a context variable, you will see a yellow exclamation mark until you have a formula that references it.
    Thor

  • Exchange 2010 Limit certain users from sending external mail

    Hi 
    I would like to know if its possible to limit certain users in a Mailstore from sending external emails?
    I am able to limit individual users but not users in particular mailstores. 
    Is it possible? If so how do i go about it?
    VeeCT

    Hi VeeCT,
    Agree with Amit. And the basic steps are as follows:
    Creat a new Distribution Group,  add the users to the group.
    Creat a new Transport Rule to restrict the group.
    Hope it helps
    Best regards

  • Delivering Mail to Multiple users from Consolidated External Mailbox

    Hi everyone
    I'm new to the use of postfix, spamassassin and so on to send and recieve email. On PCs when setting up a small server at home, or with students to demonstrate some of the issues involoved I've used the rather nicely set up Mercury Mail system.
    Now I have my own MacMini with OSX Server 10.6.x on it and want to do the same things as I used to do.
    POP email from my ISP. The ISP email boxes act as central consolidation points for two or more domains.
    Because my DSL connection may be allocated a different IP address when it drops, it has been easier to direct mail this way.
    Mail to @mydomain.com and @anotherdomain.com all go to one mailbox at the ISP (thanks to my DNS registry).
    Mail may also be retrieved from a GMail account via POP3 or similar to be consolidated on the server/backed up locally.
    What I need to do:
    - Mail needs to be retrieved from the mailboxes
    - Mail needs to be checked for SPAM level and marked as SPAM as needed
    - The OSX server via Postfix (?) needs to redirect mail to the appropriate OD user
    - If no appropriate user detected then mail is copied to the postmaster account and bounced.
    I have seen various tutorials out there for fetchmail/mpop out there but found them a tad confusing.
    I have also seen replacement software, but I want to make use of the built in systems such as fetchmail to do what I want.
    It would also be nice to have the passwords stored in the keychain for a little more security.
    Can anyone help with a suitable guide or willing to help me write a guide to tell people how to do this?
    Cheers
    Ady

    OK so I have found from various sources, and through trial and error that I am able to do the following in a shell script:
    --- start script ---
    user=<ISP USERNAME>
    isp=<ISP NAME>
    server=<SERVER NAME AT ISP eg mail>
    TMPFILE=`mktemp /tmp/fm.XXXXXX` || exit 1
    password=$(security find-internet-password -s $server.$isp -a $user -g 2>&1 | perl -ne '/password: "(\S*)"/ and print $$
    cat <<EoF > $TMPFILE
    set postmaster '<LOCAL POSTMASTER ACCOUNT>'
    set bouncemail
    poll $server.$isp with proto POP3 and options no dns
    user "$user" there with password '$password'
    options fetchall keep mda '/usr/bin/procmail -d %T'
    EoF
    fetchmail -v -f $TMPFILE
    rm -f $TMPFILE
    --- end of script ---
    thanks to http://serverfault.com/questions/149452/how-can-i-use-fetchmail-or-another-email -grabber-with-osx-keychain-for-authenti
    and for the autostart fetchmail on boot from http://discussions.apple.com/thread.jspa?threadID=2218143&tstart=225
    making this executable and putting in the /etc folder as run-fetchmail is the first step
    Now this works to deliver messages to the local mail, but you need to access it via the terminal - hmmm...
    the fetchall is to grab all the messages even read ones whilst I test...
    so I tried removing the mda section so it used the default mda on snow leopard, but the message are not being delivered to the respective users mail.app accessible mailboxes.
    I will add daemon to the file once I have the fetching working correctly
    so - how on earth do I get the mail to be delivered to the Mail.app accessible mail delivery agent?

  • How do I copy a mac user from an external drive?

    At the apple store about 2 weeks ago now they rold me that the hard drive was busted and I needed a new one. So, the hard drive was too damaged to make a disk image so they made a copy of my profile using terminal to my external drive. How would I moving the profile back on my new drive.

    Copy the contents of the folder on the external drive to your user folder on the new hard drive. Example - replace the Music folder with the old one. If you have folders that are the same name it should ask you if it is okay to replace the new ones. Be sure you don't have anything in the folders you replace, as you would lose any contents.

  • Stopping Users from Web Surfing Externally Using IE?

    We have a lot of legacy internal application that can only be accessed using IE.
    Due to the recent Microsoft announcement concerning IE versions and support/patching. We want to stop users from surfing externally using IE, is there a policy setting (or proxy config, host file mod etc.) that we can use to force this?

    Hello,
    block your firewall for port 80/443 explicit and then open only required ports for your requirements.
    For controlling internet access you have the need for proxy server. A free proxy server is SQUID
    http://www.squid-cache.org/
    Best regards
    Meinolf Weber
    MVP, MCP, MCTS
    Microsoft MVP - Directory Services
    My Blog: http://blogs.msmvps.com/MWeber
    Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.
    Twitter:  

  • Show/Search Users from specific organization in OIM

    Hello Everyone,
    I have a requirement where in when a request is submitted and forwarded to say Manager. Now, Manager should reassign the task to other user who is from particular organization say MyOrg1. Is it possible to implement this. Currently, when I try to reassign the task to some other user, it provides me users from all the Organizations. It should show only those users who are from MyOrg1 and should not show users from other Organizations.
    Please let me know.
    Thanks,

    In R2 it is very simple. just provide Organization Viwer/Administrator Admin Role on other organization to Manager . Now manager can assign to other user who exist under other org.
    I don't know if it is possible in R1. you can check with the Object PermPolicy. do the same as R2. I mean provide viwer permission on this organization
    Look at data object permission tab and there also you can provied read access for Organization Admin role.
    For R1 find below link
    http://docs.oracle.com/cd/E21764_01/doc.1111/e14316/org_mangmnt.htm#CHDFBDDB
    and
    http://docs.oracle.com/cd/E21764_01/doc.1111/e14316/org_mangmnt.htm#BABGFGAJ

  • How can i use labview.tl​b to control Labview from an external applicatio​n?

    Hi,
    I've been told by a labview engineer that i could use the file
    labview.tlb located in the labview install folder to control labview
    from an external application (in my case, a C# app). I'm using Labview
    6.1 under Windows 2000. This article confirms that:
    "ActiveX and LabVIEW"
    http://zone.ni.com/devzone/conceptd.nsf/webmain/54​01BE584FBAEECE862567C2006D36C7?opendocument
    But i've not been able to find out how to use this file to achieve
    what i want. I just want to be able to open/close labview, open/close
    a vi, start/stop a vi, hide/show a vi from a C# application. The above
    web page talks about activex but i really don't see the realtion
    between activex and that labview.tlb file.
    Is there so
    mebody around who knows how to use that file? Why does NI
    tell us that it's possible to do what i want to do but doesn't explain
    how (or hides this info very well)?
    Thanks

    Hi,
    > Hi I am fighting a similar problem and so far I found this: Calling
    > LabVIEW from C++ Using ActiveX
    >
    > http://sine.ni.com/apps/we/niepd_web_display.DISPL​AY_EPD4?>p_guid=B45EACE3E21356A4E034080020E74861&p​_node=DZ52051&p_submitted=N&p_rank=&p>_answer=&p_s​ource=External
    Thanks for the link, i actually already found this link before. I've
    found yesterday how to use Labview.tlb, just add it to the references
    of the project, it was probably too easy for me at that time:-) But
    now, i'm still stuck as there is no doc about using the interfaces and
    classes of this activex to control labview.
    The example given on your link is made is C++ and for some reasons,
    the wrapper generated for Labview.tlb when i added it to my c# project
    doesn't seem to expose the same
    interfaces and classes as the one used
    in the C++ example. I therefore can't use the C++ example in C#.
    I've tried to do something like:
    LabVIEW.ApplicationClass a = new LabVIEW.ApplicationClass();
    Just this line causes labview to launch but then immediately throws an
    exception: "Query interface for interface LabVIEW._IApplication
    failed".
    Does somebody knows how to use that control in C#/VB.NET ?

  • Creating a server rule that watches for mail from an external user

    We need to create a rule that will watch for incoming mail from an external domain and then forward that mail to an internal distribution list. I don't want it to be tied to an Outlook user. Is this possible? I can't seem to find a way to do this. 
    Orange County District Attorney

    Hello,
    Please make sure your exchange version.
    If you use exchange 2007/2010, there is no this transport rule to realize it. But you can create a transport rule( from users inside or outside the organization; copy the message to addresses) to copy incoming mail from an external domain to your distribution
    list.
    If you have any feedback on our support, please click
    here
    Cara Chen
    TechNet Community Support

  • External table authentication not updating user group changes

    Hello
    I have a question..
    In OBIEE, i am using external table authentication. I have user and user group tables where users and groups are stores.. Every Time I create a new user and assign them to a group, these records get inserted immediately to these tables with the correct user and group ID that matches with each other.. Then in my initialization block I have the query that fetches the user name and psswd as well as groups names..
    All these are working at the initial user creation. For example, when I create user A and assign it to group A, the DB table has all of the records inserted correctly. When I log in to OBIEE using User A login, I see it is assigned to Group B.
    The problem comes when I change the user A from Group B to Group C. When I did that, although the DB table gets updated correctly, OBIEE session seems to still be the previous one. As a result, when I log in the second time, I see the user A is still assigned to Group B instead of Group C.. This seems to be cached..
    I double check these user tables in OBIEE, none of them are cache enabled.. The connection pool setting of the isolation level is set as default..
    When I reinstall OBIEE all over again and re-log in the first time, this User is now assigned to Group C..
    So seems to be that it is caching issue.
    How should I go about solving this issue
    Appreciate in advance

    Make sure you check the box for 'Required for authentication' and also 'Use caching' should not check.
    Edited by: Srini VEERAVALLI on May 15, 2013 9:05 PM

  • How do I copy backed-up files from an external hard drive back to my MBA, but under a different user than the one from which they were backed up?

    On the advice of the Chicago Mac Genius Bar, in order to get better performance on my few years old MBA, I copied my Home folders (but not Library) to an external hard drive, created a new user, deleted the old user, and tried to copy the Home folder contents from the external hard drive back to the MBA under the new user. However, I get an error message and can't open most of the folders on the external hard drive (e.g. "The folder “Desktop” can’t be opened because you don’t have permission to see its contents.") Help! Thanks.

    As captfred says, yes (as long as the drive is formatted for a Mac, not Windoze).
    You might want to review the [Time Machine Tutorial|http://www.apple.com/findouthow/mac/#timemachinebasics] and perhaps browse [Time Machine - Frequently Asked Questions|http://web.me.com/pondini/Time_Machine/FAQ.html] (or use the link in *User Tips* at the top of this forum).

Maybe you are looking for